Analysis · 1 August 2026 · computed from our published data

What actually grounds AI assurance?

We mapped 649 AI assurance controls across 332 published sources, from legislation and standards to incident reports and academic research. Along the way we realized something surprising: citation counts don't tell you which sources matter most.

Some references touch hundreds of controls without deeply grounding any of them. Others influence only a handful of controls, yet hold the only deep grounding those controls have in our corpus.

Measuring both breadth and depth reveals a very different picture of AI governance.

How the scores work. The unit is a source-to-control mapping. Each mapping carries a documented fit grade, direct, partial, supporting or adjacent, assigned at ingestion and checked in review. Breadth is the number of distinct controls a source maps. Depth is the average fit weight across a source's assessed mappings (direct 1.0, partial 0.6, supporting and adjacent 0.3). Uniqueness credits each control in proportion to how few sources share it. The map shows sources with 15 or more mapped controls; backbone, specialist and supporting labels come from breadth, depth and concentration thresholds recorded in the published, signed value.json, whose meta.method states every formula. A high depth score does not by itself make a source more authoritative: a narrow source can score high because it is mapped only where its fit is strongest. Of the 332 registered sources, 305 are cited by at least one control and are the ones scored here; the rest are registered references not yet mapped. One number in an earlier data cut counted mapping rows rather than distinct controls in two per-area subtotals; this version counts distinct controls throughout.
MeasureWhat it capturesWhat it does not establish
BreadthNumber of distinct controls a source mapsImportance or authority
DepthAverage directness of those mappingsThe overall quality of a source
UniquenessHow scarce alternative grounding is in this corpusAbsence from all published literature
Area rankAverage mapping depth within an areaHow complete that area is

Two kinds of value

The map below plots every substantial source. Breadth runs across: how many controls a source helps ground. Depth runs up: how directly it grounds them. Two broad roles emerge, though some sources fill both. A few broad frameworks stretch across the whole map; the EU AI Act, for one, is both the widest-reaching source and among the deeper ones. Far more numerous are the specialists, narrow but deep, each the strongest voice in its own lane. Filter by area to see who shows up where.

Backbone: broad, ties the map together Specialist: deep in one lane Supporting

Broad frameworks connect many controls across areas, and often carry their own authority as law or standard. Within most individual areas, though, specialists provide the most direct grounding. The same split repeats when you look area by area.

The pattern repeats, area by area

Twelve areas of assurance, ordered by average grounding depth in our mappings, deepest first. Knowledge and resilience score highest. Security and model assurance draw on many sources, but their average mappings are among the least deep. The names beside each area are its three strongest mapped sources, ranked by fit-weighted mapping score.

Behind each of those leads sits a specialist doing what the broad frameworks cannot: giving one area its full depth. Without these sources, entire parts of the framework lose their deepest grounding.

Value also hides in narrow places.

Worth a lot, even when small

Some sources ground only a handful of controls, yet for certain controls they hold the only deep mapping in our corpus. No other source we have mapped goes as far on those controls. However small, these earn their place, because losing one leaves a control with no deep grounding at all.

The only source in our corpus with deep mappings to seven controls, including securing agents that live in the browser, governing agents installed on employee machines, and modeling agentic threats at design time.
A classic security catalog, supplying the only deep mappings in our corpus for six authority controls adapted from established approval and audit practices. The old guard covering the newest ground.
Nothing else in our corpus covers drift detection or behavioral boundary testing at this depth. Nine deep mappings in total, two of them currently unmatched by any other source we mapped.
Provides the deepest threat grounding in our corpus for controls on backdoors and training-data memorization; on those two it stands alone among the sources we mapped.
Its identity-lifecycle concepts give our corpus its deepest grounding for the controls we apply to abandoned agent identities and cross-organization delegation.
A single mapping in our corpus, and nothing else we mapped covers it: making AI explanations accessible to the people who need them.

These narrow sources answer a fair question about any large reference list: is the long tail padding? Here it is not. The tail is where several controls get their only deep grounding in the corpus. And measuring uniqueness this way exposed something larger than any single source.

One finding stood apart

Across eleven of the twelve assurance areas, the grounding in our corpus was merely uneven. In the agent-authority portion, one kind of grounding was absent: an end-to-end framework for agent-created organizational commitments, one that defines what an autonomous agent may commit an organization to, how that authority is delegated, where its limits end, and who ultimately remains accountable.

Because our own control structure shapes where a gap can appear, we treated this as a hypothesis rather than a verdict. We then searched deliberately, beyond the mapped corpus, for a framework that covered the full chain. The closest published attempt we found is a February 2026 IETF Internet-Draft on agent operation authorization: it specifies action-specific authorization, cryptographically bound user consent, and signed agent-to-agent delegation chains. It covers a real and important slice, but as a work-in-progress technical draft, not the organizational lifecycle, the aggregate commitment limits, the contracting obligations, the segregation of duties, and the board-level accountability that a commitment actually needs. Within the sources we mapped, and in that wider search, we found no published framework that governs the whole of it end to end.

That gap led directly to our own public proposal. Rather than waiting for a standard to emerge, we synthesized the available evidence, the IETF draft included, into a six-layer reference model and published it for challenge and refinement: When an agent acts for you.

Two limits worth naming. This analysis measures how much a source contributes to our control corpus; it does not yet score a source's external authority, its independence, or its currency, which is why a vendor guide and a binding law can sit near each other on the map. And sources enter the corpus through our ingestion process for the controls, not through a systematic literature search, so this is an analysis of the Apeiris collection, stated as such, not a survey of the whole field.

These results are calculated from Apeiris corpus version 2026.08.01, computed on 1 August 2026, covering 649 controls and 332 registered sources (305 cited by at least one control). Breadth, depth and uniqueness are computed consistently from the published source-to-control mappings; the mapping classifications themselves reflect documented analytical judgment and are open to review. Results describe this corpus and should not be read as a census of all published AI assurance literature. About 95 percent of framework citations are checked against source text available to us; separately, a blinded three-reviewer cross-model panel (OpenAI and Anthropic models) reviewed a 120-mapping stratified sample, agreeing at Krippendorff's alpha 0.779 (ordinal) with zero invalid citations (full results); the remainder cite proprietary sources whose text cannot be redistributed. The underlying data is open and CC BY 4.0.